U.S. CISA adds Multiple Cisco Small Business RV Series Routers, Hitachi Vantara Pentaho BA Server, Microsoft Windows Win32k, and Progress WhatsUp Gold flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-8639 | Kernel-mode privilege escalation in Microsoft Windows Win32k CVE-2018-8639 is an improper resource shutdown or release flaw (CWE-404) in the Windows Win32k kernel component. A local, authenticated attacker can trigger the faulty resource handling and leverage it to execute arbitrary code in kernel mode, the highest privilege level on a Windows system. Successful exploitation effectively yields full system control (SYSTEM-equivalent), making it useful both for escalating from a low-privileged foothold and as a step in post-compromise activity, including ransomware operations. All Microsoft Windows versions covered by the vendor's advisory for this CVE are affected; the source data does not specify exact version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2025-03-03 with known ransomware use, and EPSS estimates a 22.2% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. Do: Apply Microsoft's security updates for all affected Windows releases immediately per vendor instructions, prioritizing servers, shared workstations, and systems where untrusted users can run code, since the flaw is in the CISA KEV catalog with known ransomware use. Follow applicable BOD 22-01 guidance for cloud services, or discontinue use where mitigations are unavailable. Until patched, restrict local code execution by untrusted accounts and monitor for unusual privilege-escalation activity. | 7.8 | 22% | KEV ransomware |
| masswell over 1 billion Windows installations worldwide | |
| CVE-2022-43939 +1 in the same advisory: …43769 | Authorization Bypass in Hitachi Vantara Pentaho Business Analytics Server Hitachi Vantara Pentaho Business Analytics (BA) Server versions before 9.4.0.1 and 9.3.0.2, including all 8.3.x releases, enforce security restrictions using non-canonical URL checks (CWE-647), so an attacker can circumvent authentication and authorization with crafted, non-canonical URL variants. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1 score of 9.8), meaning a remote unauthenticated attacker can reach protected functionality simply by sending specially formed URLs to the server. A public proof-of-concept (published on Packet Storm) demonstrates the authentication bypass chained with server-side template injection (SSTI) to achieve code execution. Organizations running affected Pentaho BA Server versions — typically enterprises using the platform for BI reporting and analytics — are affected, particularly where the server is reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, confirming exploitation in the wild, and EPSS assigns it a 92.3% probability of exploitation within 30 days (100th percentile). Do: Upgrade Pentaho BA Server to 9.4.0.1 or 9.3.0.2 or later; 8.3.x deployments are also affected and must move to a fixed release per Hitachi Vantara's guidance. Federal agencies must apply the required BOD 22-01 mitigations per the KEV listing (or discontinue use if mitigations are unavailable). All defenders should identify internet-exposed Pentaho instances, restrict access to trusted networks where possible, and hunt for indicators of the authentication bypass/SSTI exploitation chain. | 9.8 group max | 92% | KEV PoC |
| moderate≈1,000–10,000 deployments (estimate; no authoritative install count available) | |
| CVE-2023-20118 | Authenticated Command Injection in Cisco Small Business RV Series Routers CVE-2023-20118 is a command injection flaw (CWE-77) in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers, caused by improper validation of user input within incoming HTTP packets. An authenticated remote attacker who already holds valid administrative credentials sends a crafted HTTP request to the management interface and can execute arbitrary commands with root-level privileges, gaining full device control and access to unauthorized data. All organizations running these six small-business router models are affected, and Cisco has stated it will not release any software update, leaving only a workaround. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, carries a high EPSS score of 54.1%, and news reporting around that period describes campaigns (e.g., ViciousTrap, which built a global honeypot from roughly 5,300 compromised devices) abusing Cisco router flaws, with botnet operators such as PolarEdge also targeting Cisco small-business routers. These end-of-service devices are therefore under active, in-the-wild exploitation and should be treated as high-priority for mitigation. Do: No firmware fix will ever be released, so apply Cisco's workaround by disabling the affected feature or restricting the web management interface to trusted management hosts only (disable remote/internet-facing management). Check device logs and configurations for signs of compromise, including unexpected configuration changes or outbound connections indicating botnet implants. Because these routers are end-of-service, plan migration to supported models and, for federal agencies, follow BOD 22-01 mitigation guidance or discontinue use. | 7.2 | 54% | KEV |
| largetens of thousands of internet-exposed devices (order-of-magnitude estimate; at least ~5,300 already confirmed compromised in one reported campaign) | |
| CVE-2024-4885 | Unauthenticated Path Traversal RCE in Progress WhatsUp Gold CVE-2024-4885 is an unauthenticated path traversal vulnerability (CWE-22) in the WhatsUp.ExportUtilities.Export.GetFileWithoutZip function of Progress WhatsUp Gold, a network monitoring platform. An attacker can send a crafted request to the affected export/file-retrieval functionality to traverse outside the intended directory, which leads to execution of commands on the server. Successful exploitation yields remote code execution running with the privileges of the iisapppool\mconsole application pool identity, giving control of the WhatsUp Gold monitoring server and, potentially, a foothold in the network. All WhatsUp Gold versions released before 2023.1.3 are affected, meaning any organization running an unpatched on-premises deployment is exposed, especially if the web interface is reachable from untrusted networks. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-03, and its 99.3% EPSS probability reflects very high expected exploitation; no public PoC is known, though headlines indicate exploitation followed shortly after a proof-of-concept for this WhatsUp Gold flaw. Do: Upgrade WhatsUp Gold to version 2023.1.3 or later, per Progress's advisories (which shipped patches for this and several related WhatsUp Gold flaws). Until patched, restrict access to the WhatsUp Gold web interface to trusted networks and review logs for unexpected requests to the export utility; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the KEV due date. Because the flaw is unauthenticated and exploited in the wild, treat any internet-facing, unpatched instance as compromised until verified. | 9.8 | 99% | KEV |
| moderatelow thousands of internet-exposed WhatsUp Gold servers; total on-prem deployments plausibly in the tens of thousands |
Full article433 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Small Business RV Series Routers, Hitachi Vantara Pentaho BA Server, Microsoft Windows Win32k, and Progress WhatsUp Gold flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2023-20118 Cisco Small Business RV Series Routers Command Injection Vulnerability
- CVE-2022-43939 Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
- CVE-2022-43769 Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
- CVE-2018-8639 Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
- CVE-2024-4885 Progress WhatsUp Gold Path Traversal Vulnerability
Below are the descriptions for these flaws:
CVE-2023-20118 (CVSS score 6.5) – the vulnerability resides in Cisco Small Business Routers’ web interface and allows authenticated remote attackers to execute arbitrary commands due to improper input validation. Exploiting it requires admin credentials and grants root access. Cisco will not release a fix for this issue.
“Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow a remote attacker to bypass authentication or execute arbitrary commands on the underlying operating system of an affected device.” reads the advisory.
CVE-2018-8639 (CVSS score of 7.8) – an elevation of privilege vulnerability that impacts Windows when the Win32k component fails to properly handle objects in memory. An attacker could exploit the vulnerability to run arbitrary code in kernel mode, and then install programs; view, change, or delete data; or create new accounts with full user rights.
“To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.” reads the advisory. “The update addresses this vulnerability by correcting how Win32k handles objects in memory.”
CVE-2024-4885 (CVSS score 9.8) – an unauthenticated Remote Code Execution vulnerability impacts Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.
The US Agency also added two Hitachi Vantara Pentaho BA Server flaws, respectively tracked as CVE-2022-43939 and CVE-2022-43769, to the catalog.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by March 24, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174853/security/u-s-cisa-adds-multiple-cisco-small-business-rv-series-routers-hitachi-vantara-pentaho-ba-server-microsoft-windows-win32k-and-progress-whatsup-gold-flaws-to-its-known-exploited-vulnerabilities.html